— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for Spotify.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"allows_bounty_splitting": true,
"average_time_to_bounty_awarded": 1379,
"average_time_to_first_program_response": 78,
"average_time_to_report_resolved": 1982,
"handle": "spotify",
"id": 0,
"managed_program": true,
"name": "Spotify",
"offers_bounties": true,
"offers_swag": false,
"response_efficiency_percentage": 81,
"submission_state": "open",
"url": "https://hackerone.com/spotify",
"website": "https://spotify.com",
"targets": {
"in_scope": [
{
"asset_identifier": "*.atspotify.com",
"asset_type": "WILDCARD",
"availability_requirement": "low",
"confidentiality_requirement": "low",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "If a bug you have submitted affects a site managed by a third party we will award you a $100 bonus payment and close the report as informational.",
"integrity_requirement": "low",
"max_severity": "low"
},
{
"asset_identifier": "*.avecspotify.com",
"asset_type": "WILDCARD",
"availability_requirement": "low",
"confidentiality_requirement": "low",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "If a bug you have submitted affects a site managed by a third party we will award you a $100 bonus payment and close the report as informational.",
"integrity_requirement": "low",
"max_severity": "low"
},
{
"asset_identifier": "*.byspotify.com",
"asset_type": "WILDCARD",
"availability_requirement": "low",
"confidentiality_requirement": "low",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "If a bug you have submitted affects a site managed by a third party we will award you a $100 bonus payment and close the report as informational.",
"integrity_requirement": "low",
"max_severity": "low"
},
{
"asset_identifier": "*.enspotify.com",
"asset_type": "WILDCARD",
"availability_requirement": "low",
"confidentiality_requirement": "low",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "If a bug you have submitted affects a site managed by a third party we will award you a $100 bonus payment and close the report as informational.",
"integrity_requirement": "low",
"max_severity": "low"
},
{
"asset_identifier": "*.forspotify.com",
"asset_type": "WILDCARD",
"availability_requirement": "low",
"confidentiality_requirement": "low",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "If a bug you have submitted affects a site managed by a third party we will award you a $100 bonus payment and close the report as informational.",
"integrity_requirement": "low",
"max_severity": "low"
},
{
"asset_identifier": "*.fromspotify.com",
"asset_type": "WILDCARD",
"availability_requirement": "low",
"confidentiality_requirement": "low",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "If a bug you have submitted affects a site managed by a third party we will award you a $100 bonus payment and close the report as informational.",
"integrity_requirement": "low",
"max_severity": "low"
},
{
"asset_identifier": "*.spotify.com",
"asset_type": "WILDCARD",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "[Non-core asset]\n\nMain spotify domain wildcard for assets on this domain that are not otherwise listed.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "*.spotify.net",
"asset_type": "WILDCARD",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "[Non-core asset]\n\nInternal spotify domain wildcard for assets on this domain that are not otherwise listed.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "*.tospotify.com",
"asset_type": "WILDCARD",
"availability_requirement": "low",
"confidentiality_requirement": "low",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "If a bug you have submitted affects a site managed by a third party we will award you a $100 bonus payment and close the report as informational.",
"integrity_requirement": "low",
"max_severity": "low"
},
{
"asset_identifier": "*.withspotify.com",
"asset_type": "WILDCARD",
"availability_requirement": "low",
"confidentiality_requirement": "low",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "If a bug you have submitted affects a site managed by a third party we will award you a $100 bonus payment and close the report as informational.",
"integrity_requirement": "low",
"max_severity": "low"
},
{
"asset_identifier": "Anchor",
"asset_type": "OTHER",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Anchor was acquired by Spotify in 2019.\n\n[Non-core asset]\n\n~~~\nanchor.fm",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "Android SDK",
"asset_type": "SOURCE_CODE",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "[Core asset]\n\n* https://developer.spotify.com/documentation/android/ \n* https://github.com/spotify/android-sdk ",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "Core Assets",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": null,
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Core Backstage source code",
"asset_type": "SOURCE_CODE",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "https://github.com/backstage/backstage\n\n[Core asset]\n\nNote on severity - per Backstage's [threat model](https://backstage.io/docs/overview/threat-model/), Backstage is primarily designed to be deployed in a protected environment rather than being exposed to the public internet. We assume an **internal** deployment when reviewing the CVSS criteria, such as the attack vector and complexity.\n\nThe following components are considered Core Assets. Reports on any other component should be submitted to the \"Non-Core Backstage source code\" asset.\n\n@backstage/app-defaults\n@backstage/backend-app-api\n@backstage/backend-common\n@backstage/backend-defaults\n@backstage/backend-dev-utils\n@backstage/backend-openapi-utils\n@backstage/backend-plugin-api\n@backstage/backend-test-utils\n@backstage/catalog-client\n@backstage/catalog-model\n@backstage/cli\n@backstage/cli-common\n@backstage/cli-node\n@backstage/config\n@backstage/config-loader\n@backstage/core-app-api\n@backstage/core-compat-api\n@backstage/core-components\n@backstage/core-plugin-api\n@backstage/dev-utils\n@backstage/e2e-test-utils\n@backstage/errors\n@backstage/frontend-app-api\n@backstage/frontend-defaults\n@backstage/frontend-plugin-api\n@backstage/frontend-test-utils\n@backstage/integration\n@backstage/integration-aws-node\n@backstage/integration-react\n@backstage/plugin-api-docs\n@backstage/plugin-app\n@backstage/plugin-app-backend\n@backstage/plugin-app-visualizer\n@backstage/plugin-auth-backend\n@backstage/plugin-auth-backend-module-github-provider\n@backstage/plugin-auth-backend-module-gitlab-provider\n@backstage/plugin-auth-backend-module-google-provider\n@backstage/plugin-auth-backend-module-guest-provider\n@backstage/plugin-auth-backend-module-microsoft-provider\n@backstage/plugin-auth-backend-module-oauth2-proxy-provider\n@backstage/plugin-auth-backend-module-okta-provider\n@backstage/plugin-auth-node\n@backstage/plugin-auth-react\n@backstage/plugin-catalog\n@backstage/plugin-catalog-backend\n@backstage/plugin-catalog-backend-module-azure\n@backstage/plugin-catalog-backend-module-github\n@backstage/plugin-catalog-backend-module-github-org\n@backstage/plugin-catalog-backend-module-gitlab\n@backstage/plugin-catalog-backend-module-gitlab-org\n@backstage/plugin-catalog-backend-module-incremental-ingestion\n@backstage/plugin-catalog-backend-module-logs\n@backstage/plugin-catalog-backend-module-msgraph\n@backstage/plugin-catalog-backend-module-scaffolder-entity-model\n@backstage/plugin-catalog-backend-module-unprocessed\n@backstage/plugin-catalog-common\n@backstage/plugin-catalog-graph\n@backstage/plugin-catalog-import\n@backstage/plugin-catalog-node\n@backstage/plugin-catalog-react\n@backstage/plugin-catalog-unprocessed-entities\n@backstage/plugin-events-backend\n@backstage/plugin-events-backend-module-azure\n@backstage/plugin-events-backend-module-github\n@backstage/plugin-events-backend-module-gitlab\n@backstage/plugin-events-node\n@backstage/plugin-home\n@backstage/plugin-home-react\n@backstage/plugin-kubernetes\n@backstage/plugin-kubernetes-common\n@backstage/plugin-mcp-actions-backend\n@backstage/plugin-notifications\n@backstage/plugin-notifications-backend\n@backstage/plugin-notifications-common\n@backstage/plugin-org\n@backstage/plugin-org-react\n@backstage/plugin-permission-backend\n@backstage/plugin-permission-common\n@backstage/plugin-permission-node\n@backstage/plugin-permission-react\n@backstage/plugin-proxy-backend\n@backstage/plugin-scaffolder\n@backstage/plugin-scaffolder-backend\n@backstage/plugin-scaffolder-backend-module-azure\n@backstage/plugin-scaffolder-backend-module-github\n@backstage/plugin-scaffolder-backend-module-gitlab\n@backstage/plugin-scaffolder-common\n@backstage/plugin-scaffolder-react\n@backstage/plugin-search\n@backstage/plugin-search-backend\n@backstage/plugin-search-backend-module-catalog\n@backstage/plugin-search-backend-module-pg\n@backstage/plugin-search-backend-module-techdocs\n@backstage/plugin-search-backend-node\n@backstage/plugin-search-common\n@backstage/plugin-search-react\n@backstage/plugin-signals\n@backstage/plugin-signals-backend\n@backstage/plugin-signals-node\n@backstage/plugin-signals-react\n@backstage/plugin-techdocs\n@backstage/plugin-techdocs-addons-test-utils\n@backstage/plugin-techdocs-backend\n@backstage/plugin-techdocs-common\n@backstage/plugin-techdocs-module-addons-contrib\n@backstage/plugin-techdocs-node\n@backstage/plugin-techdocs-react\n@backstage/plugin-user-settings\n@backstage/release-manifests\n@backstage/repo-tools\n@backstage/test-utils\n@backstage/theme\n@backstage/types\n@backstage/ui\n@backstage/version-bridge",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "DRM (Digital Rights Management) System",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "[Core Asset]\nWe are interested in reports about the DRM used to secure the content on Spotify, specifically for these DRM implementations and versions. More info on the DRM is available in the program guidelines.\n\n- playplay DRM system vulnerabilities on mobile client versions 9.1.38+\n- playplay DRM system vulnerabilities on desktop client versions >= 1.2.89",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "GHE",
"asset_type": "OTHER",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "[Core asset]",
"integrity_requirement": "not_defined",
"max_severity": "critical"
},
{
"asset_identifier": "Jira",
"asset_type": "OTHER",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "[Core asset]",
"integrity_requirement": "not_defined",
"max_severity": "critical"
},
{
"asset_identifier": "Megaphone",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Megaphone was acquired by Spotify in November 2020.\n\n[Core asset]\n\n** These targets are NOT in scope:**\n```\nsupport.megaphone.fm\n```",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Non-Core Assets",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": null,
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Okta",
"asset_type": "OTHER",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "[Core asset]",
"integrity_requirement": "not_defined",
"max_severity": "critical"
},
{
"asset_identifier": "Other Spotify websites",
"asset_type": "OTHER",
"availability_requirement": "low",
"confidentiality_requirement": "low",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Please use this asset for non *.spotify.com websites. This includes sites associated with Spotify, but aren't otherwise listed as a separate asset.\n[Non-core asset]\nFind below a list of in-scope targets. Note that it is continuously updated:\n\n```\neyeofthestormers.com\nlifeatspotify.com\nsonalytic.com\nspotify.design\nspotifycharts.com\nspotifycodes.com\nspotifycs.my.salesforce.com\nspotifyforpartners.com\nspotifyforvendors.com\nspotifynewsroom.jp\nspotifyonstage.com\nspotifypremium.jp\nspotifyvault.com\ntimetoplayfair.com\n```",
"integrity_requirement": "low",
"max_severity": "critical"
},
{
"asset_identifier": "Podsights",
"asset_type": "OTHER",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Podsights was acquired by Spotify in February 2022. \n\n[ Non-core asset]\n\n** These targets are in scope: **\n```\nadmin.podsights.com\napi.pdst.fm\ncdn.pdst.fm\ndash.podsights.com\nmetarouter.pdst.io\npdst.fm\nping.pdst.fm\npodcast-graph-dot-adaptive-growth.appspot.com\npodsights.com\nsink.pdst.fm\n```",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "Save to Spotify CLI",
"asset_type": "DOWNLOADABLE_EXECUTABLES",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "[Non-Core asset] \n\nThis only includes the CLI and the skill.\n* https://github.com/spotify/save-to-spotify\n* https://clawhub.ai/spotify/save-to-spotify",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Sonantic",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Sonantic was acquired by Spotify in June 2022. \n\n[Non-core asset]\n\n** These targets are in scope: **\n```\napp.sonantic.io\napi.sonantic.io\nlabel-studio-public.sonantic.io\n```",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Spotify SDKs",
"asset_type": "SOURCE_CODE",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "For Spotify SDK (note: there is a specific scope for Web, Android and iOS SDK)\nhttps://developer.spotify.com/\n\n[Core asset]\n",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Spotify desktop application (Windows and Mac)",
"asset_type": "DOWNLOADABLE_EXECUTABLES",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "[Core asset]",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "VPN",
"asset_type": "OTHER",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": null,
"integrity_requirement": "not_defined",
"max_severity": "critical"
},
{
"asset_identifier": "Web Playback SDK",
"asset_type": "SOURCE_CODE",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "* https://developer.spotify.com/documentation/web-playback-sdk/\n\n[Non-core asset]",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "Wrapped",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Please use this asset when reporting bugs related to [Spotify Wrapped](https://www.spotify.com/wrapped).\n\nThis asset supersedes other assets when the issue primarily concerns Spotify Wrapped, even if it’s observed on another surface.\n\n[Core asset]",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "api-partner.spotify.com",
"asset_type": "API",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "api-partner.spotify.com\n\n[Core asset]\n\napi-partner is used by Spotify's partners, aka Ads API. It's documentation is available @ https://developer.spotify.com/documentation/ads-api",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "api.spotify.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "api.spotify.com\n\n[Core asset]\n\nBased on simple REST principles, the Spotify Web API endpoints return JSON metadata about music artists, albums, and tracks, directly from the Spotify Data Catalogue.\nWeb API also provides access to user related data, like playlists and music that the user saves in the Your Music library. Such access should be enabled through selective authorization, by the user.\nA full list of the objects returned by the endpoints of the Spotify Web API - https://developer.spotify.com/documentation/web-api/",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "assets.spotify.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "* Do not run automated scans against this target. They are often very noisy.\n~~~\nassets.spotify.com",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "backstage.io",
"asset_type": "URL",
"availability_requirement": "low",
"confidentiality_requirement": "low",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Backstage is an open-source developer portal.\n\n[Non-core asset]\n\nFind below a list of in-scope targets. Note that it is continuously updated: \n\n~~~\nbackstage.io",
"integrity_requirement": "low",
"max_severity": "medium"
},
{
"asset_identifier": "com.anchorfminc.Anchor",
"asset_type": "APPLE_STORE_APP_ID",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "[Non-core asset]",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "com.spotify.client",
"asset_type": "APPLE_STORE_APP_ID",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Spotify - Music and Podcasts\n\n[Core asset]\n\nhttps://itunes.apple.com/us/app/spotify-music-and-podcasts/id324684580",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "com.spotify.kids",
"asset_type": "APPLE_STORE_APP_ID",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Spotify Kids\n\n[Core asset]\n\nhttps://apps.apple.com/ie/app/Spotify-Kids/id1470209570",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "com.spotify.kids",
"asset_type": "GOOGLE_PLAY_APP_ID",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Spotify Kids\n\n[Core asset]\n\nhttps://play.google.com/store/apps/details?id=com.spotify.kids",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "com.spotify.music",
"asset_type": "GOOGLE_PLAY_APP_ID",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Spotify - Music and Podcasts\n\nhttps://play.google.com/store/apps/details?id=com.spotify.music\n\n[Core asset]",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "com.spotify.s4a",
"asset_type": "APPLE_STORE_APP_ID",
"availability_requirement": null,
"confidentiality_requirement": "none",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Spotify for Artists\n\n[Core asset]\n\nhttps://itunes.apple.com/us/app/spotify-for-artists/id1222021797",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "com.spotify.s4a",
"asset_type": "GOOGLE_PLAY_APP_ID",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Spotify for Artists\n\n[Core asset]\n\nhttps://play.google.com/store/apps/details?id=com.spotify.s4a",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "com.spotify.tv.android",
"asset_type": "GOOGLE_PLAY_APP_ID",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Spotify Music - for Android TV\n\nhttps://play.google.com/store/apps/details?id=com.spotify.tv.android\n\n[Core asset]",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "fm.anchor.android",
"asset_type": "GOOGLE_PLAY_APP_ID",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "[Non-core asset]",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "https://github.com/backstage/backstage",
"asset_type": "SOURCE_CODE",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Non-Core Backstage source code\n\nhttps://github.com/backstage/backstage\n\n[Non-Core asset] This asset includes all components of the repo that are **not** part of the \"Core Backstage source code\" asset\n\nNote on severity - per Backstage's [threat model](https://backstage.io/docs/overview/threat-model/), Backstage is primarily designed to be deployed in a protected environment rather than being exposed to the public internet. We assume an **internal** deployment when reviewing the CVSS criteria, such as the attack vector and complexity.\n",
"integrity_requirement": null,
"max_severity": "medium"
},
{
"asset_identifier": "https://www.whosampled.com/",
"asset_type": "URL",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "[Non-core asset]\n\nReports accepted for the whosampled website only and the `/apimob/` API. Whosampled mobile apps are out of scope.",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "iOS SDK",
"asset_type": "SOURCE_CODE",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "* https://developer.spotify.com/documentation/ios/ \n* https://github.com/spotify/ios-sdk \n\n[Core asset]",
"integrity_requirement": "high",
"max_severity": "critical"
}
],
"out_of_scope": [
{
"asset_identifier": "Findaway",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Findaway was acquired by Spotify in June 2022. \n\nNo Findaway assets are currently in scope. Including:\n```\nfindawayvoices.com\nfindaway.com\nfindawayworld.com\n```",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "Preact",
"asset_type": "OTHER",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Preact was acquired by Spotify in 2016.\n\npreact.io is no longer owned by Spotify and is out of scope for this program",
"integrity_requirement": "high",
"max_severity": "none"
},
{
"asset_identifier": "Soundtrap",
"asset_type": "OTHER",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Soundtrap was acquired by Spotify in 2017.\n\nSoundtrap is no longer owned by Spotify and is out of scope for this program.",
"integrity_requirement": "high",
"max_severity": "none"
},
{
"asset_identifier": "The Ringer",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "The Ringer was acquired by Spotify in February 2020 but has not been onboarded to its Bug Bounty Program.\n~~~\n99music.theringer.com\n99music.theringer.com\nbesttv.theringer.com\nfantasyfootball.theringer.com\nfastfood.theringer.com\nheists.theringer.com\ninflight.theringer.com\nnbadraft.theringer.com\nnfldraft.theringer.com\nsuperheroes.theringer.com\ntheringer.com\nthrones.theringer.com\ntradevalue.theringer.com",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "com.soundtrap.studioapp",
"asset_type": "APPLE_STORE_APP_ID",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Soundtrap \n\nhttps://itunes.apple.com/us/app/soundtrap/id991031323",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "com.soundtrap.studioapp",
"asset_type": "GOOGLE_PLAY_APP_ID",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Soundtrap - Make Music Online\n\nhttps://play.google.com/store/apps/details?id=com.soundtrap.studioapp",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "everynoise.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "example.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
}
]
}
}com.anchorfminc.Anchor· criticalcom.spotify.client· criticalcom.spotify.kids· criticalcom.spotify.s4a· criticalAndroid SDK· criticalCore Backstage source code· criticalSpotify SDKs· criticalWeb Playback SDK· criticalgithub.com/backstage/backstage· mediumiOS SDK· criticalAnchor· criticalCore Assets· criticalDRM (Digital Rights Management) System· criticalGHE· criticalJira· criticalMegaphone· criticalNon-Core Assets· criticalOkta· criticalOther Spotify websites· criticalPodsights· criticalSave to Spotify CLI· criticalSonantic· criticalSpotify desktop application (Windows and Mac)· criticalVPN· criticalWrapped· criticalcom.spotify.kidsFindawayPreactSoundtrapThe Ringercom.soundtrap.studioappcom.spotify.s4a· critical